Skip to content

Autopsy Hands-on Labs

Choose the browser simulation for coached evidence review, or complete the Full Lab with Autopsy and a supplied, verified Windows training image.

Hands-on proof of concept

Scope it. Find it. Corroborate it.

Create a bounded examination, follow one deleted-file lead across Autopsy views, and state only what the evidence supports.

⏱ Setup: 20–30 min · Exercise: 45–60 min◆ Guided beginner✓ Evidence required

Interactive Lab

Full Lab

Isolated Windows VM · Setup: 20–30 min · Exercise: 45–60 min

Autopsy Full Lab

Installed Autopsy, verified image and evidence storage required

Use supplied or authorised training evidence

Analyse a verified working copy, not protected original evidence. Keep the case directory and exports separate from the image, and do not execute files recovered from the training source.

Before you begin

You need: an isolated Windows analysis VM, Autopsy, a documented Windows E01 or VMDK training image, sufficient case/index storage and separate export storage.

Case question

Does the image contain evidence that the named training file was present and deleted, and which independent Autopsy views corroborate that limited conclusion?

Objective

For case SUSA-AUT-031, add the verified working image, configure proportionate ingest, investigate the controlled keyword mimikatz.exe, compare keyword and deleted-file evidence, add time context, and write a reproducible conclusion without claiming execution or user intent.

01

Activity 1: Establish the case boundary

  1. Record authority, question, image filename, format, byte size, source and SHA-256.
  2. Verify the working-copy hash against the recorded source value.
  3. Record Autopsy version, workstation time zone, case path and export path.
  4. Create case SUSA-AUT-031 and add the working image as Disk Image or VM File.
  5. Confirm the generated or specified host remains attributable to the image.
Milestone 1Case boundary recordedCase, host, image identity, integrity and storage locations are reviewable.

Expected result The verified source appears under the intended host and no protected original has been opened.

02

Activity 2: Ingest and investigate

  1. Enable Recent Activity, Keyword Search and other modules required by the supplied image; record every enabled module and relevant setting.
  2. Start ingest and record start time, completion state, warnings and errors.
  3. Search for mimikatz.exe using a substring match restricted to the training source.
  4. Record result count and one attributable result with source, path and timestamp.
  5. Review Data Artifacts, Deleted Files or Recycle Bin for a related record.
  6. Inspect file metadata or content safely; do not execute or open recovered binaries outside a controlled viewer.
Milestone 2Two attributable leads recordedThe keyword and deleted-file observations retain their image, host, path and time context.

Expected result At least two Autopsy views point to the same controlled filename without losing provenance.

03

Activity 3: Corroborate and report

  1. Open a relevant result in Timeline and record the time zone, timestamp type, range and filters.
  2. Compare the sequence with browser or recent-activity results when available.
  3. Export only the required table or report to controlled storage and hash it.
  4. Separate observations, interpretation, confidence and limitations.
  5. State whether the evidence supports presence and deletion, and identify what additional evidence would be needed to assess execution or user attribution.

Use this structure:

Case and question:
Image, host and SHA-256:
Autopsy version and ingest modules:
Keyword observation:
Deleted-file observation:
Timeline context and time zone:
Conclusion and confidence:
What the evidence does not prove:
Export path and SHA-256:
Milestone 3Finding is reproducibleAnother analyst can repeat the search and distinguish the supported conclusion from its limits.

Full Lab evidence checklist

  • Core completion

    Required for a reviewable image examination.

0 of 7 recorded Mark each item after saving it.

Troubleshooting

Symptom First check
Image cannot be added Verify format, path, permissions, free space and working-copy integrity.
Ingest is slow Review selected modules, image size, case volume capacity and current ingest progress.
Expected artefact is absent Confirm module selection, source scope, search match type and whether the artefact exists in the supplied image.
Times appear inconsistent Record Autopsy display time zone and compare the timestamp type and source metadata.
Export cannot be reviewed Preserve its source result, export format, destination path and calculated hash.

Clean up

Close the case, protect the case directory, notes and exports, confirm no file was executed from the image, remove disposable working material when authorised and restore the analysis VM snapshot if required.